Package database

Every package we've recorded in a supply-chain compromise

3,613 packages and 9,256 package–version pairs across 152 incidents. Every entry traces back to a public advisory cited on the incident page.

Rather than browse, just check your lockfile - it matches your whole dependency tree against all of these at once, in your browser.